mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 04:27:29 +00:00
Update docs and some UI to make Admin SSO bypass more clear
This commit is contained in:
@@ -70,7 +70,7 @@ description: "Learn how to configure Auth0 OIDC for Infisical SSO."
|
|||||||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -76,7 +76,7 @@ description: "Learn how to configure Auth0 SAML for Infisical SSO."
|
|||||||
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
Once you've completed this requirement, you can toggle the **Enforce SAML SSO** button to enforce SAML SSO.
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -109,7 +109,7 @@ description: "Learn how to configure Microsoft Entra ID for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -70,7 +70,7 @@ Prerequisites:
|
|||||||
We recommend ensuring that your account is provisioned using the identity provider prior to enforcing OIDC SSO to prevent any unintended issues.
|
We recommend ensuring that your account is provisioned using the identity provider prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -84,7 +84,7 @@ description: "Learn how to configure Google SAML for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
|
|||||||
@@ -89,7 +89,7 @@ description: "Learn how to configure JumpCloud SAML for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ description: "Learn how to configure Keycloak OIDC for Infisical SSO."
|
|||||||
prior to enforcing OIDC SSO to prevent any unintended issues.
|
prior to enforcing OIDC SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -128,7 +128,7 @@ description: "Learn how to configure Keycloak SAML for Infisical SSO."
|
|||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
<Info>
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
</Info>
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -96,10 +96,10 @@ description: "Learn how to configure Okta SAML 2.0 for Infisical SSO."
|
|||||||
We recommend ensuring that your account is provisioned the application in Okta
|
We recommend ensuring that your account is provisioned the application in Okta
|
||||||
prior to enforcing SAML SSO to prevent any unintended issues.
|
prior to enforcing SAML SSO to prevent any unintended issues.
|
||||||
</Warning>
|
</Warning>
|
||||||
<Info>
|
|
||||||
In case of a lockout, an organization admin can use the admin login portal in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
|
||||||
</Info>
|
|
||||||
|
|
||||||
|
<Info>
|
||||||
|
In case of a lockout, an organization admin can use the [Admin Login Portal](https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal) in the `/login/admin` path e.g. https://app.infisical.com/login/admin.
|
||||||
|
</Info>
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
|
|||||||
@@ -39,18 +39,30 @@ If your required identity provider is not shown in the list above, please reach
|
|||||||
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
|
For enhanced security, Infisical enforces PKCE (Proof Key for Code Exchange) with the OAuth 2.0-based SSO providers and OIDC. This provides additional protection against authorization code interception attacks and strengthens your authentication flow security.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
|
## Admin Login Portal
|
||||||
|
|
||||||
|
Organization Admins can utilize the Admin Login Portal to bypass SSO enforcement in case of an emergency.
|
||||||
|
|
||||||
|
This portal is accessible at `/login/admin` (e.g., https://app.infisical.com/login/admin).
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
This bypass functionality is exclusively available to **Organization Admins**. **Server Admins** are not permitted to use this feature.
|
||||||
|
</Note>
|
||||||
|
|
||||||
## FAQ
|
## FAQ
|
||||||
|
|
||||||
<AccordionGroup>
|
<AccordionGroup>
|
||||||
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
|
<Accordion title="Why does Infisical require additional email verification for users connected via SAML?">
|
||||||
By default, Infisical Cloud is configured to not trust emails from external
|
By default, Infisical Cloud is configured to not trust emails from external
|
||||||
identity providers to prevent any malicious account takeover attempts via
|
identity providers to prevent any malicious account takeover attempts via
|
||||||
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
|
email spoofing. Accordingly, Infisical creates a new user for anyone provisioned
|
||||||
through an external identity provider and requires an additional email
|
through an external identity provider and requires an additional email
|
||||||
verification step upon their first login.
|
verification step upon their first login.
|
||||||
|
|
||||||
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
|
If you're running a self-hosted instance of Infisical and would like it to trust emails from external identity providers,
|
||||||
you can configure this behavior in the Server Admin Console.
|
you can configure this behavior in the Server Admin Console.
|
||||||
|
</Accordion>
|
||||||
</Accordion>
|
<Accordion title="Why do I get redirected to SSO when trying to use the Admin Login Portal?">
|
||||||
|
You are likely being redirected because you're not using your username and password, or you're not an **Organization Admin**. This portal requires **Organization Admin** status and direct credential login (username and password). **Server Admin** status alone is insufficient.
|
||||||
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
|
|||||||
+10
-1
@@ -129,7 +129,16 @@ export const OrgGeneralAuthSection = () => {
|
|||||||
level.
|
level.
|
||||||
</span>
|
</span>
|
||||||
<p className="mt-4">
|
<p className="mt-4">
|
||||||
In case of a lockout, admins can use the admin login portal at{" "}
|
In case of a lockout, admins can use the{" "}
|
||||||
|
<a
|
||||||
|
target="_blank"
|
||||||
|
className="underline underline-offset-2 hover:text-mineshaft-300"
|
||||||
|
href="https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal"
|
||||||
|
rel="noreferrer"
|
||||||
|
>
|
||||||
|
Admin Login Portal
|
||||||
|
</a>{" "}
|
||||||
|
at{" "}
|
||||||
<a
|
<a
|
||||||
target="_blank"
|
target="_blank"
|
||||||
rel="noopener noreferrer"
|
rel="noopener noreferrer"
|
||||||
|
|||||||
@@ -212,7 +212,16 @@ export const OrgOIDCSection = (): JSX.Element => {
|
|||||||
level.
|
level.
|
||||||
</span>
|
</span>
|
||||||
<p className="mt-4">
|
<p className="mt-4">
|
||||||
In case of a lockout, admins can use the admin login portal at{" "}
|
In case of a lockout, admins can use the{" "}
|
||||||
|
<a
|
||||||
|
target="_blank"
|
||||||
|
className="underline underline-offset-2 hover:text-mineshaft-300"
|
||||||
|
href="https://infisical.com/docs/documentation/platform/sso/overview#admin-login-portal"
|
||||||
|
rel="noreferrer"
|
||||||
|
>
|
||||||
|
Admin Login Portal
|
||||||
|
</a>{" "}
|
||||||
|
at{" "}
|
||||||
<a
|
<a
|
||||||
target="_blank"
|
target="_blank"
|
||||||
rel="noopener noreferrer"
|
rel="noopener noreferrer"
|
||||||
|
|||||||
Reference in New Issue
Block a user